GSEC Access Control and Password Management Practice Question
A security administrator is hardening authentication on a set of Linux servers that will be accessed by third-party contractors. Management requires that contractors authenticate with a one-time code delivered by a hardware token, while local administrators continue to use their existing passwords, and that both methods can be used on the same SSH service without changing the client software. Which approach best meets these requirements?
⚠ Common exam trap
The trap here is assuming that stacking every PAM module with a requisite flag automatically satisfies mixed authentication requirements, when it actually forces all factors on all accounts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy RADIUS backed by a token server, point sshd at PAM's pam_radius_auth.so, and let the RADIUS policy assign token authentication to contractor accounts and password authentication to administrator accounts.
The requirement is per-account, per-method authentication on a shared SSH service with no client changes. A RADIUS-backed token server reached through PAM lets the authentication policy decide which accounts need a hardware token and which may use a password, while sshd continues to use its normal PAM stack. This preserves existing clients and separates the two populations cleanly, matching every stated constraint.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy RADIUS backed by a token server, point sshd at PAM's pam_radius_auth.so, and let the RADIUS policy assign token authentication to contractor accounts and password authentication to administrator accounts.
Why this is correct
RADIUS centralizes the decision of which authentication method each account must satisfy. Contractors are mapped to token-based policies while administrators retain password authentication, and because sshd still calls PAM, the existing SSH clients need no changes. This satisfies every constraint in the scenario without duplicating credentials locally.
- ✗
Configure PAM to stack pam_unix.so and pam_google_authenticator.so with the requisite control flag in /etc/pam.d/sshd so both factors are required for every account.
Why it's wrong here
Stacking pam_unix.so and pam_google_authenticator.so with a requisite flag forces both a password and a one-time code for every login, including the local administrators who are supposed to keep password-only access. It also breaks the requirement that each group authenticate with only its assigned method, so this configuration fails the stated scenario.
- ✗
Set PasswordAuthentication to no and ChallengeResponseAuthentication to yes in sshd_config, then distribute hardware tokens to all accounts so every user supplies a one-time code.
Why it's wrong here
Disabling PasswordAuthentication and enabling challenge-response forces a one-time code for all users, which removes the password-only path that local administrators require. Although it technically supports tokens over unmodified SSH clients, it violates the requirement that administrators keep their existing password authentication, so it is not the right fit.
- ✗
Issue each contractor an SSH certificate signed by an internal CA and configure sshd with TrustedUserCAKeys, leaving administrator accounts on password authentication.
Why it's wrong here
SSH certificates provide strong key-based authentication but do not deliver a one-time code from a hardware token, so the contractor requirement is unmet. It also introduces client-side key handling that the scenario explicitly wants to avoid by keeping existing clients unchanged. The approach is plausible for key management but wrong for token-based OTP delivery.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.